
A supplier says they've changed their bank details
Treat any 'we've changed banks' request as unverified until you confirm by phone on a number you already hold. That one call…
Read →
Account takeover
Account takeover is when a criminal gains control of your account using stolen, guessed or phished credentials, then misuses it.
Read →
Administrator role
The administrator role is the account role able to add and remove users, set roles, and change account settings.
Read →
Advance-fee and fake loan-offer scams
A fake loan offer promises easy funding, then asks for an upfront 'release', 'insurance' or 'admin' fee before the money arrives…
Read →
Advance-fee fraud
Advance-fee fraud is a scam that promises funding — such as a loan — then asks for an upfront fee to 'release' it, after which…
Read →
Anti-money laundering (AML)
Anti-money laundering (AML) refers to the legal obligations and checks that prevent the financial system being used to disguise…
Read →
Authenticator app
An authenticator app generates a fresh six-digit code every 30 seconds on your phone, used as the second factor when you sign in.
Read →
Authorised user
An authorised user is someone you've formally added to your account with a defined role, so they can be recognised, verified and…
Read →
CEO fraud
CEO fraud is a scam in which a criminal impersonates a director or senior figure to pressure an employee into making an urgent,…
Read →
Checking a link before you click it
Before you click a link in any message about your finance, check where it really goes. It takes ten seconds and stops most…
Read →
Checking a website address is genuine
Before you type your password, make sure you're on the real credicorp.co.uk — check the exact address, the padlock, and reach the…
Read →
Choosing a strong passphrase for your business account
A passphrase — three or four unrelated words — is both stronger and easier to remember than the old-style short password with a…
Read →
Complaining about data or privacy
If you are unhappy with how we have handled your data, tell us first — we aim to put it right quickly. You can also escalate to…
Read →
Credential stuffing
Credential stuffing is an automated attack that tries username-and-password pairs leaked from one site against many others,…
Read →
Credit reference agency
A credit reference agency (CRA) collects and provides credit information about businesses and individuals, which lenders use to…
Read →
Data breach
A data breach is a security incident in which personal data is lost, stolen, or accessed by someone without authorisation.
Read →
Data controller
A data controller is the organisation that determines the purposes and means of processing personal data, and carries the primary…
Read →
Data subject access request (DSAR)
A data subject access request (DSAR) is your legal right to receive a copy of the personal data an organisation holds about you,…
Read →
Direct debit
A direct debit is an authorised instruction that lets a company collect payments from your bank account on set dates, protected…
Read →
Encryption
Encryption converts data into an unreadable form that only someone with the correct key can decode, protecting it in transit and…
Read →
Giving and revoking open banking permission
Open banking is opt-in and read-only — you authorise it through your own bank, it can only view data, and you can withdraw it at…
Read →
How Credit Corp protects your business data
Your data is protected by layered measures: encryption in transit and at rest, strict access control, and continuous monitoring…
Read →
How Credit Corp verifies your business identity
Before we lend, we confirm your company and its directors are genuine — standard identity, KYC and anti-money-laundering checks…
Read →
How long Credit Corp keeps your data
We keep data only as long as we have a lawful reason — while your facility is live, and for a defined retention period after —…
Read →
How to recognise genuine Credit Corp communications
Knowing what a genuine Credit Corp message looks like is your best defence against impersonation. We will never ask for your full…
Read →
How we verify your identity on the phone
Before we discuss or change anything sensitive, we verify that it is really you. Here is what that involves, why it protects you,…
Read →
How your data is used in lending decisions
A lending decision uses your company figures, credit reference data and, with your permission, open banking to assess…
Read →
I can see a login I don't recognise
An unfamiliar sign-in in your activity might be innocent or might be an intruder. Sign it out, change your password, and check…
Read →
I forgot to sign out on a shared computer
Left a session open on a machine you can't get back to? Sign out of all other devices from your own phone or laptop to close it…
Read →
I got a suspicious call claiming to be Credit Corp
If a caller claiming to be us pressures you for details, a code or a payment, hang up and call back on a trusted number. Genuine…
Read →
I got an email asking me to log in to 'verify' my account
An email demanding you log in through a link to 'verify' or 'secure' your account is a classic phishing sign. Don't click — sign…
Read →
I received a 2FA code I didn't request
An unexpected 2FA code usually means someone has your password and is trying to sign in. Don't share it — change your password…
Read →
I think I paid a fraudulent invoice
If you've paid a fraudulent or redirected invoice, speed is everything: contact your bank immediately, then report it and warn…
Read →
I want a copy of everything you hold on me
For your personal data, make a data subject access request. For your account transactions, download statements or export your…
Read →
I want to check my account hasn't been tampered with
Worried but no specific alert? Run a quick self-check: sessions, users, bank details, contact email and 2FA. Five minutes buys…
Read →
I want to report a scam using your name
If a scam is impersonating Credit Corp, report it to us — it helps us get fake sites and numbers taken down and protects other…
Read →
I want to stop marketing but keep service messages
You can switch off marketing entirely — it's an absolute right — while keeping the essential service messages and security alerts…
Read →
I want to tighten security after a scare
A near-miss is a good prompt. In fifteen minutes you can move from 'probably fine' to genuinely hard to compromise: passkey, 2FA,…
Read →
I was offered a loan I didn't apply for
An unsolicited, too-easy loan offer that asks for an upfront fee is a classic advance-fee scam. Genuine funding never charges you…
Read →
I'm being pressured to act urgently about my account
Manufactured urgency is the scammer's main tool. A genuine request survives you slowing down to check; a scam falls apart. So…
Read →
I'm worried about identity theft as a director
Directors are public on Companies House, which raises the risk. Use a service address, enable Companies House protections, and…
Read →
If your data may have been affected by a breach
If a breach were ever likely to put your data at risk, we would tell you and the regulator within the required timescales and set…
Read →
Information Commissioner's Office (ICO)
The Information Commissioner's Office (ICO) is the UK's independent authority upholding information rights and data-protection…
Read →
Invoice and mandate fraud, explained
Invoice fraud tricks you into paying a genuine-looking bill to a criminal's account; mandate fraud changes the bank details you…
Read →
Invoice fraud
Invoice fraud (or invoice redirection) uses a genuine-looking invoice with changed bank details to divert your payment to a…
Read →
Is it safe to connect open banking?
Yes — open banking is regulated, read-only, and revocable. You grant view-only access through your own bank, and it can never…
Read →
Keeping the devices you use for the account secure
Your account is only as secure as the device you sign in from. Keep those devices updated, locked, and free of dubious software —…
Read →
Keeping your account safe on public Wi-Fi
Public Wi-Fi is lower-risk than it used to be thanks to encrypted connections, but a few precautions — your own device, a private…
Read →
Keeping your account safe on shared or public computers
On a machine you do not fully control, treat every session as temporary: use a private window, never save the password, and sign…
Read →
Keeping your recovery codes safe
Recovery codes are your backup way in if you lose your phone. Store them somewhere safe and separate from your phone — a password…
Read →
Know Your Customer (KYC)
Know Your Customer (KYC) is the set of identity and business-verification checks a regulated lender must carry out before and…
Read →
Least privilege
Least privilege is the principle of granting each person the minimum access required for their role — no standing rights they do…
Read →
Legitimate interest
Legitimate interest is a lawful basis for using personal data where an organisation has a genuine need that isn't overridden by…
Read →
Making a data subject access request
You have the right to a copy of the personal data we hold about you — a data subject access request, or DSAR. It is free in most…
Read →
Managing trusted devices and active sessions
Your account keeps a list of the devices and browsers currently signed in. Reviewing it — and removing anything unfamiliar — is…
Read →
Mandate fraud
Mandate fraud is when a criminal persuades you to change the bank details you hold for a supplier or service, so payments go to…
Read →
Moving your authenticator to a new phone
Getting a new phone? Move your authenticator across before you wipe the old one — or use a recovery code to re-enrol. Here is the…
Read →
Multi-factor authentication (MFA)
Multi-factor authentication (MFA) requires two or more independent factors — something you know, have or are — to sign in, of…
Read →
My business email was hacked — is my finance account at risk?
A hacked business email is serious because password resets and alerts often flow through it. Secure the email, then lock down…
Read →
Objecting to or restricting how your data is used
You can object to some uses of your data — marketing is an absolute right to opt out — and ask us to restrict processing while a…
Read →
Open banking
Open banking lets you securely share read-only access to your business bank data with a lender, so affordability can be assessed…
Read →
Passkey
A passkey signs you in using your device's own unlock (fingerprint, face or PIN) instead of a typed password, and cannot be…
Read →
Passphrase
A passphrase is a password made of several unrelated words — long, memorable, and much harder to guess than a short complex…
Read →
Personal data
Personal data is any information relating to an identifiable living individual — for a business account, typically the details of…
Read →
Persons of significant control (PSC)
A person of significant control (PSC) is someone who ultimately owns or controls a company — for example holding over 25% of…
Read →
Phishing
Phishing is a fraudulent email, text or call designed to trick you into revealing login details or moving money, usually by…
Read →
Protecting director details from impersonation
A director's name, role and correspondence address are public record. That transparency is the law — but a few sensible steps…
Read →
Recovery codes
Recovery codes are one-time backup codes generated when you set up two-factor authentication, used to sign in if you lose your…
Read →
Reporting a lost or stolen device
If a device with access to your account goes missing, act in this order: sign out the device remotely, change your password, and…
Read →
Reporting suspected fraud to Credit Corp
If you spot something wrong — a scam pretending to be us, a strange login, an unexpected change — report it fast. Quick reporting…
Read →
Requesting erasure of your data
You can ask us to erase your personal data, but the right is not absolute: while you have a live facility, and for a period…
Read →
Right to erasure
The right to erasure (the 'right to be forgotten') lets you ask an organisation to delete your personal data — but it is limited…
Read →
Running a quarterly account security review
Security drifts if left alone. A five-minute review every quarter keeps it tight: check users, access, 2FA and recent sign-ins.
Read →
SIM-swap fraud
SIM-swap fraud is when a criminal transfers your mobile number to their SIM, so they receive your SMS security codes and calls.
Read →
Securing your Credit Corp business account: the full guide
The single place to lock down your Credit Corp business account — covering the password, two-factor authentication, passkeys,…
Read →
Service address
A service address is the official correspondence address a company director can register at Companies House instead of their home…
Read →
Session (sign-in session)
A session is a period during which a particular device or browser stays signed in to your account without re-entering your…
Read →
Setting up a passkey for your Credit Corp account
A passkey replaces your password with your device's own unlock — fingerprint, face or PIN. It is phishing-proof by design,…
Read →
Setting up an authenticator app for two-factor authentication
Two-factor authentication adds a second step to sign-in: after your password you enter a six-digit code from an app on your…
Read →
Smishing
Smishing is phishing by text message: a scam SMS that pushes you to click a link or call a number to 'confirm' or 'secure' your…
Read →
Social engineering
Social engineering is the manipulation of people — through urgency, authority or trust — to make them reveal information, grant…
Read →
Someone may know my account password
If you think anyone knows your password — a former colleague, or after a phishing scare — change it now and enable 2FA. Assume…
Read →
Spotting a fake invoice or payment request
Before paying any invoice with new or changed bank details, run a few checks — the key one being verify by phone on a trusted…
Read →
Spotting fake Credit Corp social media and adverts
Scammers clone brands on social media and in adverts. Verify any 'Credit Corp' account or ad by going to credicorp.co.uk yourself…
Read →
Spotting phishing emails and smishing texts
Phishing (fake emails) and smishing (fake texts) try to trick you into handing over login details or moving money. A handful of…
Read →
Trusted device
A trusted device is one you designate as yours, so it may skip the two-factor prompt for a set period — appropriate only for…
Read →
Turning on alerts for bank-detail changes
A bank-detail change is exactly the event you want to hear about instantly. Turn on the bank-change alert so mandate fraud can't…
Read →
Turning on security alerts for your account
Security alerts email you the moment something sensitive changes — a new sign-in, a password reset, a change to your repayment…
Read →
Two-factor authentication (2FA)
Two-factor authentication (2FA) is a second proof of identity — usually a code from an app — required in addition to your…
Read →
Using a password manager for your business
A password manager generates and stores a unique, strong password for every site, so you only remember one. It is the…
Read →
Vishing
Vishing is phishing by phone: a fraudster calls pretending to be your bank or lender to extract details or push you into moving…
Read →
What data Credit Corp holds about your business and why
We hold only the data we need to lend responsibly and run your account: company and director details, financial information, and…
Read →
What happens when you sign out everywhere
Sign out of all other devices ends every session except the one you're using — a fast way to cut off anything you don't control,…
Read →
What information you should never share
Some details should never leave your head or your device: your full password, one-time codes, passkey secrets and full card or…
Read →
What to do if you entered details on a fake site
If you typed your login or details into a fake page, act fast: change your password, review sessions, and report it. Speed limits…
Read →
What to do if you shared your password
If your password has been shared, phished or reused somewhere breached, change it now and turn on 2FA — in that order. It takes…
Read →
Why we ask security questions
Security questions confirm it's really you before we do anything sensitive. They're a protection, not an obstacle — the same…
Read →
Why your account sometimes asks for a code more often
An extra 2FA prompt is usually a good sign — the account is being cautious about something unusual, like a new device, network or…
Read →Funding for UK limited companies
Credit Corp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.